Skip to content

fix(csp): add jspreadsheet logo to CSP - #859

Open
MaciekBaron wants to merge 1 commit into
mainfrom
CMS-1336-add-jspreadsheet-logo-csp
Open

MaciekBaron wants to merge 1 commit into
mainfrom
CMS-1336-add-jspreadsheet-logo-csp

Conversation

@MaciekBaron

@MaciekBaron MaciekBaron commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

What is the context of this PR?

This MR addresses CMS 1336 and adds a URL to the jspreadsheet logo to our CSP, so that it does not get rejected upon loading.

Note even though the ticket uses http:// in the URL, only the https:// version was added – my understanding is that we shouldn't be loading content over http in any scenario, and therefore the CSP rejecting it is a good thing.

How to review

Ensure that tests pass.

Deployment Safety

Bleed and Sandbox deploy automatically on merge, so PRs should be safe to deploy immediately.

Please select one:

  • Safe to auto-deploy
  • Not safe to auto-deploy

Follow-up Actions

Potentially consider only adding this to the CSP when necessary and not on every page load.


Ticket: CMS-1336

@MaciekBaron
MaciekBaron requested a review from a team as a code owner October 1, 2026 15:55
@helenb

helenb commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

I only see the CSP error in my local build intermittently, but when I do it is for an http version:

Screenshot 2026-10-02 at 08 23 38

So I'm not sure if this change addresses the issue.

I notice we allow *.hotjar.com - does that mean http is already allowed for that domain?

@MaciekBaron

Copy link
Copy Markdown
Contributor Author

@helenb I wonder if this is because the image is referenced using //bossanova.uk/jspreadsheet/logo.png which means it uses the same protocol as the page itself (so if you're using http://localhost:8000 it would use http)?

@helenb

helenb commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@helenb I wonder if this is because the image is referenced using //bossanova.uk/jspreadsheet/logo.png which means it uses the same protocol as the page itself (so if you're using http://localhost:8000 it would use http)?

You're right - just tested in sandbox and the path it reports uses https.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants